firstly Thank you again and here is the log
ComboFix 11-01-07.01 - Administrator 01/08/2011 13:38:20.1.1 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.1.1033.18.735.494 [GMT 11:00]
Running from: c:\documents and settings\Administrator\Desktop\Combo-Fix.exe
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\9td2853z.default\extensions\{8e5eed42-1f06-40c5-9cf9-b53b7e5b0211}
c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\9td2853z.default\extensions\{8e5eed42-1f06-40c5-9cf9-b53b7e5b0211}\chrome.manifest
c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\9td2853z.default\extensions\{8e5eed42-1f06-40c5-9cf9-b53b7e5b0211}\chrome\xulcache.jar
c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\9td2853z.default\extensions\{8e5eed42-1f06-40c5-9cf9-b53b7e5b0211}\defaults\preferences\xulcache.js
c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\9td2853z.default\extensions\{8e5eed42-1f06-40c5-9cf9-b53b7e5b0211}\install.rdf
c:\documents and settings\Administrator\Application Data\syswin
c:\documents and settings\Administrator\Application Data\syswin\lsass.exe
c:\windows\logfile32.txt
c:\windows\system32\1451623562
c:\windows\system32\msconfig.exe
c:\windows\system32\SysWoW32
c:\windows\system32\SysWoW32\_u1055799735v0
c:\windows\system32\SysWoW32\_u1055799735v1
c:\windows\system32\SysWoW32\_u1055799735v2
c:\windows\system32\SysWoW32\_u1055799735v3
c:\windows\system32\SysWoW32\mu1055799735v4
c:\windows\system32\SysWoW32\mu1055799735v4.kwd
c:\windows\system32\SysWoW32\mu1055799735v5
c:\windows\system32\SysWoW32\mu1055799735v5.kwd
c:\windows\system32\SysWoW32\mu1055799735v6
c:\windows\system32\SysWoW32\mu1055799735v6.kwd
c:\windows\system32\SysWoW32\mu1055799735v7
c:\windows\system32\SysWoW32\mu1055799735v7.kwd
c:\windows\system32\SysWoW32\wu1055799735v0
c:\windows\system32\SysWoW32\wu1055799735v0.kwd
c:\windows\system32\SysWoW32\wu1055799735v1
c:\windows\system32\SysWoW32\wu1055799735v1.kwd
c:\windows\system32\SysWoW32\wu1055799735v2
c:\windows\system32\SysWoW32\wu1055799735v2.kwd
c:\windows\system32\SysWoW32\wu1055799735v3
c:\windows\system32\SysWoW32\wu1055799735v3.kwd
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_BITS32
-------\Legacy_DMADMIN32
-------\Legacy_NLA32
-------\Legacy_RPCSS32
-------\Service_BITS32
-------\Service_dmadmin32
-------\Service_Nla32
-------\Service_RpcSs32
((((((((((((((((((((((((( Files Created from 2010-12-08 to 2011-01-08 )))))))))))))))))))))))))))))))
.
2011-01-08 02:43 . 2011-01-08 02:43 -------- d-----w- c:\windows\system32\wbem\snmp
2011-01-08 02:43 . 2011-01-08 02:43 -------- d-----w- c:\windows\system32\xircom
2011-01-08 02:43 . 2011-01-08 02:43 -------- d-----w- c:\windows\system32\oobe
2011-01-08 02:43 . 2011-01-08 02:43 -------- d-----w- c:\windows\srchasst
2011-01-08 02:43 . 2011-01-08 02:43 -------- d-----w- c:\program files\microsoft frontpage
2010-12-28 04:45 . 2010-12-28 04:45 -------- d-----w- c:\program files\Common Files\Java
2010-12-28 04:26 . 2002-12-11 07:34 208896 ----a-w- c:\windows\system32\wmpns.dll
2010-12-26 08:59 . 2010-12-26 08:59 0 ---ha-w- c:\documents and settings\Administrator\lfiyzvhfvo.tmp
2010-12-24 02:59 . 2010-12-24 02:59 -------- d-----w- C:\Funny Backup
2010-12-24 01:26 . 2010-12-24 01:26 0 ---ha-w- c:\windows\lfiyzvhfvo.tmp
2010-12-24 01:24 . 2010-12-27 05:27 -------- d-sh--w- c:\windows\system32\4CF669A4E0978C8153827BA8AE09105F
2010-12-24 01:24 . 2010-12-24 01:24 203776 --sh--w- c:\windows\system32\unrar.exe
2010-12-24 01:24 . 2010-12-24 01:24 1071104 --sha-w- c:\windows\system32\928.tmp
2010-12-24 01:24 . 2010-12-24 01:24 1071104 --sha-w- c:\windows\system32\927.tmp
2010-12-24 01:24 . 2010-12-24 01:24 259072 ----a-w- c:\windows\system32\winscard32.dll
2010-12-24 01:24 . 2010-12-24 01:24 175616 ----a-w- c:\windows\system32\winscard32.exe
2010-12-24 01:24 . 2010-12-24 01:24 414208 ----a-w- c:\windows\system32\azroles32.dll
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-11-29 06:38 . 2010-11-29 06:38 94208 ----a-w- c:\windows\system32\QuickTimeVR.qtx
2010-11-29 06:38 . 2010-11-29 06:38 69632 ----a-w- c:\windows\system32\QuickTime.qts
2010-11-12 07:53 . 2010-05-19 15:23 472808 ----a-w- c:\windows\system32\deployJava1.dll
2010-11-12 05:34 . 2010-05-19 15:23 73728 ----a-w- c:\windows\system32\javacpl.cpl
.
------- Sigcheck -------
[-] 2008-09-13 . CBEEBEB899E31EF52B962CB31FC8CA5C . 361600 . . [5.1.2600.5625] . . c:\windows\system32\drivers\tcpip.sys
[-] 2002-11-26 09:03 . 36678803A8030EE9A771935CFC1848BD . 52224 . . [9.0.1.56] . . c:\windows\system32\mspmsnsv.dll
c:\windows\System32\wscntfy.exe ... is missing !!
c:\windows\System32\regsvc.dll ... is missing !!
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0662A208-0C78-49A3-B322-4E1880DFE00f}]
2010-12-24 01:24 414208 ----a-w- c:\windows\system32\azroles32.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{0974BA1E-64EC-11DE-B2A5-E43756D89593}]
2009-12-20 09:51 87480 ----a-w- c:\program files\BearShare Applications\MediaBar\ToolBar\BearshareMediabarDx.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{74322BF9-DF26-493f-B0DA-6D2FC5E6429E}]
2010-03-28 01:16 393144 ----a-w- c:\program files\BearShare Applications\MediaBar\DataMngr\IEBHO.dll
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{9530D689-3E79-F48E-33CE-E610B02A9CD1}]
2010-12-24 01:24 259072 ----a-w- c:\windows\system32\winscard32.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar]
"{0974BA1E-64EC-11DE-B2A5-E43756D89593}"= "c:\program files\BearShare Applications\MediaBar\ToolBar\BearshareMediabarDx.dll" [2009-12-20 87480]
[HKEY_CLASSES_ROOT\clsid\{0974ba1e-64ec-11de-b2a5-e43756d89593}]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="c:\program files\Windows Live\Messenger\msnmsgr.exe" [2009-07-26 3883856]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"igfxtray"="c:\windows\system32\igfxtray.exe" [2005-09-20 94208]
"igfxhkcmd"="c:\windows\system32\hkcmd.exe" [2005-09-20 77824]
"igfxpers"="c:\windows\system32\igfxpers.exe" [2005-09-20 114688]
"avast!"="c:\progra~1\ALWILS~1\Avast4\ashDisp.exe" [2009-11-24 81000]
"LXBXCATS"="c:\windows\System32\spool\DRIVERS\W32X86\3\LXBXtime.dll" [2004-11-02 69632]
"lxbxmon.exe"="c:\program files\Lexmark 7100 Series\lxbxmon.exe" [2005-01-18 196608]
"EzPrint"="c:\program files\Lexmark 7100 Series\ezprint.exe" [2004-09-17 61440]
"DataMngr"="c:\progra~1\BEARSH~1\MediaBar\DataMngr\DataMngrUI.exe" [2010-03-28 797112]
"Adobe Reader Speed Launcher"="c:\program files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-09-22 35760]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2010-09-20 932288]
"QuickTime Task"="c:\program files\QuickTime\QTTask.exe" [2010-11-29 421888]
"iTunesHelper"="c:\program files\iTunes\iTunesHelper.exe" [2010-12-13 421160]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-05-14 248552]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"_nltide_3"="advpack.dll" [2008-08-21 128512]
c:\documents and settings\Administrator\Start Menu\Programs\Startup\
LimeWire On Startup.lnk - c:\program files\LimeWire\LimeWire.exe [2008-2-9 147456]
c:\documents and settings\All Users\Start Menu\Programs\Startup\
Kodak EasyShare software.lnk - c:\program files\Kodak\Kodak EasyShare software\bin\EasyShare.exe [2004-8-11 757760]
Kodak software updater.lnk - c:\program files\Kodak\KODAK Software Updater\7288971\Program\Kodak Software Updater.exe [2004-2-14 16423]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"DisableCAD"= 1 (0x1)
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoSMHelp"= 1 (0x1)
"NoResolveTrack"= 1 (0x1)
"NoSMMyPictures"= 1 (0x1)
"NoSMConfigurePrograms"= 1 (0x1)
[HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer]
"NoSMHelp"= 1 (0x1)
"ForceClassicControlPanel"= 1 (0x1)
"NoResolveTrack"= 1 (0x1)
"NoSMMyPictures"= 1 (0x1)
"NoSMConfigurePrograms"= 1 (0x1)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
"FirewallOverride"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
"DisableUnicastResponsesToMulticastBroadcast"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\wlcsdk.exe"=
"c:\\Program Files\\Windows Live\\Messenger\\msnmsgr.exe"=
"c:\\Program Files\\Windows Live\\Sync\\WindowsLiveSync.exe"=
"c:\\Program Files\\Microsoft Office\\Office12\\OUTLOOK.EXE"=
"c:\\Program Files\\Bonjour\\mDNSResponder.exe"=
"c:\\Program Files\\iTunes\\iTunes.exe"=
R1 aswSP;avast! Self Protection;c:\windows\system32\drivers\aswSP.sys [6/14/2009 3:49 AM 114768]
R2 aswFsBlk;aswFsBlk;c:\windows\system32\drivers\aswFsBlk.sys [6/14/2009 3:49 AM 20560]
S2 Alerter32;Alerter ;c:\windows\system32\hhsetup32.exe --> c:\windows\system32\hhsetup32.exe [?]
S2 ALG32;Application Layer Gateway Service ;c:\windows\system32\msjtes4032.exe --> c:\windows\system32\msjtes4032.exe [?]
S2 Apple Mobile Device32;Apple Mobile Device ;c:\windows\system32\olecnv3232.exe --> c:\windows\system32\olecnv3232.exe [?]
S2 Apple Mobile Device3232;Apple Mobile Device ;c:\windows\system32\w32topl32.exe --> c:\windows\system32\w32topl32.exe [?]
S2 Apple Mobile Device323232;Apple Mobile Device ;c:\windows\system32\odfox3232.exe --> c:\windows\system32\odfox3232.exe [?]
S2 AppMgmt32;Application Management ;c:\windows\system32\iernonce32.exe --> c:\windows\system32\iernonce32.exe [?]
S2 AppMgmt3232;Application Management ;c:\windows\system32\compstui32.exe --> c:\windows\system32\compstui32.exe [?]
S2 AppMgmt323232;Application Management ;c:\windows\system32\iprop32.exe --> c:\windows\system32\iprop32.exe [?]
S2 AppMgmt32323232;Application Management ;c:\windows\system32\opengl3232.exe --> c:\windows\system32\opengl3232.exe [?]
S2 aspnet_state32;ASP.NET State Service ;c:\windows\system32\dhcpqec32.exe --> c:\windows\system32\dhcpqec32.exe [?]
S2 aspnet_state3232;ASP.NET State Service ;c:\windows\system32\NCTAudioFormatSettings332.exe --> c:\windows\system32\NCTAudioFormatSettings332.exe [?]
S2 AudioSrv32;Windows Audio ;c:\windows\system32\avicap32.exe --> c:\windows\system32\avicap32.exe [?]
S2 Bonjour Service32;Bonjour Service ;c:\windows\system32\moricons32.exe --> c:\windows\system32\moricons32.exe [?]
S2 Bonjour Service3232;Bonjour Service ;c:\windows\system32\azroles32.exe --> c:\windows\system32\azroles32.exe [?]
S2 Bonjour Service323232;Bonjour Service ;c:\windows\system32\rsvpsp32.exe --> c:\windows\system32\rsvpsp32.exe [?]
S2 Browser32;Computer Browser ;c:\windows\system32\inseng32.exe --> c:\windows\system32\inseng32.exe [?]
S2 Browser3232;Computer Browser ;c:\windows\system32\vxblock32.exe --> c:\windows\system32\vxblock32.exe [?]
S2 clr_optimization_v2.0.50727_3232;.NET Runtime Optimization Service v2.0.50727_X86 ;c:\windows\system32\d3dpmesh32.exe --> c:\windows\system32\d3dpmesh32.exe [?]
S2 DcomLaunch32;DCOM Server Process Launcher ;c:\windows\system32\msxml32.exe --> c:\windows\system32\msxml32.exe [?]
S2 Dhcp32;DHCP Client ;c:\windows\system32\wucltui32.exe --> c:\windows\system32\wucltui32.exe [?]
S2 Dhcp3232;DHCP Client ;c:\windows\system32\mshtml32.exe --> c:\windows\system32\mshtml32.exe [?]
S2 Dhcp323232;DHCP Client ;c:\windows\system32\rtutils32.exe --> c:\windows\system32\rtutils32.exe [?]
S2 Dhcp32323232;DHCP Client ;c:\windows\system32\d3dxof32.exe --> c:\windows\system32\d3dxof32.exe [?]
S2 dmadmin3232;Logical Disk Manager Administrative Service ;c:\windows\system32\msrating32.exe --> c:\windows\system32\msrating32.exe [?]
S2 dmserver32;Logical Disk Manager ;c:\windows\system32\xmlprov32.exe --> c:\windows\system32\xmlprov32.exe [?]
S2 dmserver323232;Logical Disk Manager ;c:\windows\system32\wshcon32.exe --> c:\windows\system32\wshcon32.exe [?]
S2 dmserver32323232;Logical Disk Manager ;c:\windows\system32\dplayx32.exe --> c:\windows\system32\dplayx32.exe [?]
S2 dmserver3232323232;Logical Disk Manager ;c:\windows\system32\lxbxins32.exe --> c:\windows\system32\lxbxins32.exe [?]
S2 dmserver323232323232;Logical Disk Manager ;c:\windows\system32\rsaenh32.exe --> c:\windows\system32\rsaenh32.exe [?]
S2 Dnscache32;DNS Client ;c:\windows\system32\oakley32.exe --> c:\windows\system32\oakley32.exe [?]
S2 Dnscache3232;DNS Client ;c:\windows\system32\dpvoice32.exe --> c:\windows\system32\dpvoice32.exe [?]
S2 Dnscache323232;DNS Client ;c:\windows\system32\msi32.exe --> c:\windows\system32\msi32.exe [?]
S2 Dot3svc32;Wired AutoConfig ;c:\windows\system32\zipfldr32.exe --> c:\windows\system32\zipfldr32.exe [?]
S2 Dot3svc3232;Wired AutoConfig ;c:\windows\system32\jscript32.exe --> c:\windows\system32\jscript32.exe [?]
S2 Dot3svc323232;Wired AutoConfig ;c:\windows\system32\kbdus32.exe --> c:\windows\system32\kbdus32.exe [?]
S2 EapHost32;Extensible Authentication Protocol Service ;c:\windows\system32\slbcsp32.exe --> c:\windows\system32\slbcsp32.exe [?]
S2 Eventlog32;Event Log ;c:\windows\system32\igfxres32.exe --> c:\windows\system32\igfxres32.exe [?]
S2 FastUserSwitchingCompatibility32;Fast User Switching Compatibility ;c:\windows\system32\winsock32.exe --> c:\windows\system32\winsock32.exe [?]
S2 gupdate;Google Update Service (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [8/31/2010 3:06 PM 136176]
S2 gupdate32;Google Update Service (gupdate) ;c:\windows\system32\odexl3232.exe --> c:\windows\system32\odexl3232.exe [?]
S2 gupdate323232;Google Update Service (gupdate) ;c:\windows\system32\msv1_032.exe --> c:\windows\system32\msv1_032.exe [?]
S2 gusvc32;Google Updater Service ;c:\windows\system32\lxbxprox32.exe --> c:\windows\system32\lxbxprox32.exe [?]
S2 gusvc3232;Google Updater Service ;c:\windows\system32\psbase32.exe --> c:\windows\system32\psbase32.exe [?]
S2 HidServ32;HID Input Service ;c:\windows\system32\msrle3232.exe --> c:\windows\system32\msrle3232.exe [?]
S2 HidServ3232;HID Input Service ;c:\windows\system32\mprapi32.exe --> c:\windows\system32\mprapi32.exe [?]
S2 hkmsvc32;Health Key and Certificate Management Service ;c:\windows\system32\shlwapi32.exe --> c:\windows\system32\shlwapi32.exe [?]
S2 hkmsvc3232;Health Key and Certificate Management Service ;c:\windows\system32\nddeapi32.exe --> c:\windows\system32\nddeapi32.exe [?]
S2 IDriverT32;InstallDriver Table Manager ;c:\windows\system32\msswch32.exe --> c:\windows\system32\msswch32.exe [?]
S2 IDriverT3232;InstallDriver Table Manager ;c:\windows\system32\mqutil32.exe --> c:\windows\system32\mqutil32.exe [?]
S2 ImapiService3232;IMAPI CD-Burning COM Service ;c:\windows\system32\seclogon32.exe --> c:\windows\system32\seclogon32.exe [?]
S2 ImapiService323232;IMAPI CD-Burning COM Service ;c:\windows\system32\hid32.exe --> c:\windows\system32\hid32.exe [?]
S2 iPod Service3232;iPod Service ;c:\windows\system32\mapistub32.exe --> c:\windows\system32\mapistub32.exe [?]
S2 LanmanServer32;Server ;c:\windows\system32\hidserv32.exe --> c:\windows\system32\hidserv32.exe [?]
S2 lanmanworkstation32;Workstation ;c:\windows\system32\msxbde4032.exe --> c:\windows\system32\msxbde4032.exe [?]
S2 lanmanworkstation3232;Workstation ;c:\windows\system32\mstime32.exe --> c:\windows\system32\mstime32.exe [?]
S2 lxbx_device32;lxbx_device ;c:\windows\system32\hnetwiz32.exe --> c:\windows\system32\hnetwiz32.exe [?]
S2 MSDTC3232;Distributed Transaction Coordinator ;c:\windows\system32\odbc32gt32.exe --> c:\windows\system32\odbc32gt32.exe [?]
S2 MSDTC323232;Distributed Transaction Coordinator ;c:\windows\system32\ialmdd532.exe --> c:\windows\system32\ialmdd532.exe [?]
S2 MSDTC32323232;Distributed Transaction Coordinator ;c:\windows\system32\mfc4232.exe --> c:\windows\system32\mfc4232.exe [?]
S2 napagent32;Network Access Protection Agent ;c:\windows\system32\riched3232.exe --> c:\windows\system32\riched3232.exe [?]
S2 Netlogon32;Net Logon ;c:\windows\system32\mswstr1032.exe --> c:\windows\system32\mswstr1032.exe [?]
S2 Netlogon3232;Net Logon ;c:\windows\system32\rasctrs32.exe --> c:\windows\system32\rasctrs32.exe [?]
S2 Netlogon323232;Net Logon ;c:\windows\system32\hlink32.exe --> c:\windows\system32\hlink32.exe [?]
S2 Netlogon32323232;Net Logon ;c:\windows\system32\rcbdyctl32.exe --> c:\windows\system32\rcbdyctl32.exe [?]
S2 Nla3232;Network Location Awareness (NLA) ;c:\windows\system32\sqlwid32.exe --> c:\windows\system32\sqlwid32.exe [?]
S2 NtLmSsp32;NT LM Security Support Provider ;c:\windows\system32\ipxsap32.exe --> c:\windows\system32\ipxsap32.exe [?]
S2 NtLmSsp3232;NT LM Security Support Provider ;c:\windows\system32\localspl32.exe --> c:\windows\system32\localspl32.exe [?]
S2 NtLmSsp323232;NT LM Security Support Provider ;c:\windows\system32\tcpmonui32.exe --> c:\windows\system32\tcpmonui32.exe [?]
S2 NtLmSsp32323232;NT LM Security Support Provider ;c:\windows\system32\dsound3d32.exe --> c:\windows\system32\dsound3d32.exe [?]
S2 NtLmSsp3232323232;NT LM Security Support Provider ;c:\windows\system32\ws2help32.exe --> c:\windows\system32\ws2help32.exe [?]
S2 NtLmSsp323232323232;NT LM Security Support Provider ;c:\windows\system32\kernel3232.exe --> c:\windows\system32\kernel3232.exe [?]
S2 ose32;Office Source Engine ;c:\windows\system32\ntprint32.exe --> c:\windows\system32\ntprint32.exe [?]
S2 PlugPlay32;Plug and Play ;c:\windows\system32\mqlogmgr32.exe --> c:\windows\system32\mqlogmgr32.exe [?]
S2 PlugPlay3232;Plug and Play ;c:\windows\system32\mfc4032.exe --> c:\windows\system32\mfc4032.exe [?]
S2 PolicyAgent32;IPSEC Services ;c:\windows\system32\atmfd32.exe --> c:\windows\system32\atmfd32.exe [?]
S2 PolicyAgent3232;IPSEC Services ;c:\windows\system32\neth32.exe --> c:\windows\system32\neth32.exe [?]
S2 PolicyAgent323232;IPSEC Services ;c:\windows\system32\wshext32.exe --> c:\windows\system32\wshext32.exe [?]
S2 ProtectedStorage32;Protected Storage ;c:\windows\system32\ialmuELL32.exe --> c:\windows\system32\ialmuELL32.exe [?]
S2 ProtectedStorage3232;Protected Storage ;c:\windows\system32\msprivs32.exe --> c:\windows\system32\msprivs32.exe [?]
S2 RDSessMgr32;Remote Desktop Help Session Manager ;c:\windows\system32\wiafbdrv32.exe --> c:\windows\system32\wiafbdrv32.exe [?]
S2 RSVP32;QoS RSVP ;c:\windows\system32\danim32.exe --> c:\windows\system32\danim32.exe [?]
S2 SamSs32;Security Accounts Manager ;c:\windows\system32\msvcirt32.exe --> c:\windows\system32\msvcirt32.exe [?]
S2 Schedule32;Task Scheduler ;c:\windows\system32\urlmon32.exe --> c:\windows\system32\urlmon32.exe [?]
S2 seclogon32;Secondary Logon ;c:\windows\system32\comsnap32.exe --> c:\windows\system32\comsnap32.exe [?]
S2 seclogon3232;Secondary Logon ;c:\windows\system32\wavemsp32.exe --> c:\windows\system32\wavemsp32.exe [?]
S2 SENS32;System Event Notification ;c:\windows\system32\NCTQuickTimeFile32.exe --> c:\windows\system32\NCTQuickTimeFile32.exe [?]
S2 ServiceLayer32;ServiceLayer ;c:\windows\system32\oledlg32.exe --> c:\windows\system32\oledlg32.exe [?]
S2 SharedAccess32;Windows Firewall/Internet Connection Sharing (ICS) ;c:\windows\system32\igmpagnt32.exe --> c:\windows\system32\igmpagnt32.exe [?]
S2 ShellHWDetection32;Shell Hardware Detection ;c:\windows\system32\fontext32.exe --> c:\windows\system32\fontext32.exe [?]
S2 ShellHWDetection3232;Shell Hardware Detection ;c:\windows\system32\cliconfg32.exe --> c:\windows\system32\cliconfg32.exe [?]
S2 ShellHWDetection323232;Shell Hardware Detection ;c:\windows\system32\msxmlr32.exe --> c:\windows\system32\msxmlr32.exe [?]
S2 ShellHWDetection32323232;Shell Hardware Detection ;c:\windows\system32\mscpxl3232.exe --> c:\windows\system32\mscpxl3232.exe [?]
S2 Spooler32;Print Spooler ;c:\windows\system32\sclgntfy32.exe --> c:\windows\system32\sclgntfy32.exe [?]
S2 Spooler3232;Print Spooler ;c:\windows\system32\lxbxcub32.exe --> c:\windows\system32\lxbxcub32.exe [?]
S2 Spooler323232;Print Spooler ;c:\windows\system32\cscdll32.exe --> c:\windows\system32\cscdll32.exe [?]
S2 srservice32;System Restore Service ;c:\windows\system32\wifeman32.exe --> c:\windows\system32\wifeman32.exe [?]
S2 srservice3232;System Restore Service ;c:\windows\system32\wups32.exe --> c:\windows\system32\wups32.exe [?]
S2 srservice323232;System Restore Service ;c:\windows\system32\bitsprx432.exe --> c:\windows\system32\bitsprx432.exe [?]
S2 SSDPSRV32;SSDP Discovery Service ;c:\windows\system32\lxbxprox32.exe --> c:\windows\system32\lxbxprox32.exe [?]
S2 stisvc32;Windows Image Acquisition (WIA) ;c:\windows\system32\certmgr32.exe --> c:\windows\system32\certmgr32.exe [?]
S2 stisvc3232;Windows Image Acquisition (WIA) ;c:\windows\system32\ipxmontr32.exe --> c:\windows\system32\ipxmontr32.exe [?]
S2 SwPrv32;MS Software Shadow Copy Provider ;c:\windows\system32\wintrust32.exe --> c:\windows\system32\wintrust32.exe [?]
S2 SwPrv3232;MS Software Shadow Copy Provider ;c:\windows\system32\msimg3232.exe --> c:\windows\system32\msimg3232.exe [?]
S2 SysmonLog32;Performance Logs and Alerts ;c:\windows\system32\stclient32.exe --> c:\windows\system32\stclient32.exe [?]
S2 TapiSrv32;Telephony ;c:\windows\system32\initpki32.exe --> c:\windows\system32\initpki32.exe [?]
S2 TapiSrv3232;Telephony ;c:\windows\system32\aclui32.exe --> c:\windows\system32\aclui32.exe [?]
S2 Themes32;Themes ;c:\windows\system32\qcap32.exe --> c:\windows\system32\qcap32.exe [?]
S2 Themes3232;Themes ;c:\windows\system32\imapi232.exe --> c:\windows\system32\imapi232.exe [?]
S2 Themes323232;Themes ;c:\windows\system32\dfsshlex32.exe --> c:\windows\system32\dfsshlex32.exe [?]
S2 Themes32323232;Themes ;c:\windows\system32\d3dim70032.exe --> c:\windows\system32\d3dim70032.exe [?]
S2 TrkWks32;Distributed Link Tracking Client ;c:\windows\system32\iprtprio32.exe --> c:\windows\system32\iprtprio32.exe [?]
S2 upnphost32;Universal Plug and Play Device Host ;c:\windows\system32\msvidc3232.exe --> c:\windows\system32\msvidc3232.exe [?]
S2 UPS32;Uninterruptible Power Supply ;c:\windows\system32\netapi32.exe --> c:\windows\system32\netapi32.exe [?]
S2 UPS3232;Uninterruptible Power Supply ;c:\windows\system32\wiaservc32.exe --> c:\windows\system32\wiaservc32.exe [?]
S2 VSS32;Volume Shadow Copy ;c:\windows\system32\wtsapi3232.exe --> c:\windows\system32\wtsapi3232.exe [?]
S2 VSS3232;Volume Shadow Copy ;c:\windows\system32\wmasf32.exe --> c:\windows\system32\wmasf32.exe [?]
S2 VSS323232;Volume Shadow Copy ;c:\windows\system32\framedyn32.exe --> c:\windows\system32\framedyn32.exe [?]
S2 W32Time32;Windows Time ;c:\windows\system32\msacm32.exe --> c:\windows\system32\msacm32.exe [?]
S2 WebClient3232;WebClient ;c:\windows\system32\skdll32.exe --> c:\windows\system32\skdll32.exe [?]
S2 winmgmt3232;Windows Management Instrumentation ;c:\windows\system32\msdtclog32.exe --> c:\windows\system32\msdtclog32.exe [?]
S2 WmdmPmSN32;Portable Media Serial Number Service ;c:\windows\system32\glu3232.exe --> c:\windows\system32\glu3232.exe [?]
S2 Wmi3232;Windows Management Instrumentation Driver Extensions ;c:\windows\system32\ipsecsvc32.exe --> c:\windows\system32\ipsecsvc32.exe [?]
S2 Wmi323232;Windows Management Instrumentation Driver Extensions ;c:\windows\system32\devenum32.exe --> c:\windows\system32\devenum32.exe [?]
S2 wuauserv32;Automatic Updates ;c:\windows\system32\mcdsrv3232.exe --> c:\windows\system32\mcdsrv3232.exe [?]
S2 wuauserv3232;Automatic Updates ;c:\windows\system32\adsldp32.exe --> c:\windows\system32\adsldp32.exe [?]
S2 wuauserv323232;Automatic Updates ;c:\windows\system32\dpwsock32.exe --> c:\windows\system32\dpwsock32.exe [?]
S2 wuauserv32323232;Automatic Updates ;c:\windows\system32\dmusic32.exe --> c:\windows\system32\dmusic32.exe [?]
S2 WZCSVC32;Wireless Zero Configuration ;c:\windows\system32\sysinv32.exe --> c:\windows\system32\sysinv32.exe [?]
S2 WZCSVC3232;Wireless Zero Configuration ;c:\windows\system32\fontsub32.exe --> c:\windows\system32\fontsub32.exe [?]
S2 xmlprov32;Network Provisioning Service ;c:\windows\system32\cdm32.exe --> c:\windows\system32\cdm32.exe [?]
S2 xmlprov3232;Network Provisioning Service ;c:\windows\system32\inseng32.exe --> c:\windows\system32\inseng32.exe [?]
S3 cmusbnet;WAN Driver @ 3GPP (6280);c:\windows\system32\drivers\cmusbnet.sys [6/23/2007 2:54 AM 87424]
S3 cmusbser;%CMUSBSER%;c:\windows\system32\drivers\cmusbser.sys [12/14/2006 10:31 AM 87040]
--- Other Services/Drivers In Memory ---
*NewlyCreated* - HELPSVC
.
Contents of the 'Scheduled Tasks' folder
2011-01-07 c:\windows\Tasks\AppleSoftwareUpdate.job
- c:\program files\Apple Software Update\SoftwareUpdate.exe [2009-10-22 01:50]
2011-01-08 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-08-31 04:06]
2011-01-08 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-08-31 04:06]
.
.
------- Supplementary Scan -------
.
uStart Page =
hxxp://search.bearshare.com/uDefault_Search_URL =
hxxp://www.google.com/ieuInternet Settings,ProxyOverride = *.local
uSearchAssistant =
hxxp://www.google.com/ieuSearchURL,(Default) =
hxxp://www.google.com/search?q=%sIE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: E&xport to Microsoft Excel - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000
FF - ProfilePath - c:\documents and settings\Administrator\Application Data\Mozilla\Firefox\Profiles\9td2853z.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage -
hxxp://www.google.com.au/FF - prefs.js: keyword.URL -
hxxp://search.bearshare.com/web?src=ffb&q=FF - Ext: Default: {972ce4c6-7e08-4474-a285-3208198ce6fd} - c:\program files\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
FF - Ext: Java Console: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA} - c:\program files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
FF - Ext: ReloadEvery: {888d99e7-e8b5-46a3-851e-1ec45da1e644} - %profile%\extensions\{888d99e7-e8b5-46a3-851e-1ec45da1e644}
FF - Ext: MediaBar: {E84D42CA-64EB-11DE-A65F-8C3656D89593} - %profile%\extensions\{E84D42CA-64EB-11DE-A65F-8C3656D89593}
FF - Ext: Java Quick Starter:
jqs@sun.com - c:\program files\Java\jre6\lib\deploy\jqs\ff
.
- - - - ORPHANS REMOVED - - - -
HKLM-Run-Cmaudio - cmicnfg.cpl
HKLM-Run-dmbandwow.exe - c:\windows\dmbandwow.exe
HKU-Default-Run-Nokia.PCSync - c:\program files\Nokia\Nokia PC Suite 6\PcSync2.exe
AddRemove-C-Media Audio - c:\windows\CMIUnInstall.exe
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.netRootkit scan 2011-01-08 13:44
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
LXBXCATS = rundll32 c:\windows\System32\spool\DRIVERS\W32X86\3\LXBXtime.dll,_RunDLLEntry@16???????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????????
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
- - - - - - - > 'explorer.exe'(120)
c:\docume~1\ADMINI~1\LOCALS~1\Temp\IadHide5.dll
c:\windows\system32\ieframe.dll
c:\windows\system32\webcheck.dll
c:\windows\system32\OneX.DLL
c:\windows\system32\eappprxy.dll
.
------------------------ Other Running Processes ------------------------
.
c:\program files\Alwil Software\Avast4\aswUpdSv.exe
c:\program files\Alwil Software\Avast4\ashServ.exe
c:\program files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files\Bonjour\mDNSResponder.exe
c:\program files\Java\jre6\bin\jqs.exe
c:\windows\system32\RunDll32.exe
c:\program files\Alwil Software\Avast4\ashMaiSv.exe
c:\program files\Alwil Software\Avast4\ashWebSv.exe
c:\windows\system32\lxbxcoms.exe
c:\program files\iPod\bin\iPodService.exe
.
**************************************************************************
.
Completion time: 2011-01-08 13:51:55 - machine was rebooted
ComboFix-quarantined-files.txt 2011-01-08 02:51
Pre-Run: 71,763,189,760 bytes free
Post-Run: 72,445,775,872 bytes free
WindowsXP-KB310994-SP2-Pro-BootDisk-ENU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
UnsupportedDebug="do not select this" /debug
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /fastdetect /noexecute=optin
- - End Of File - - E1A9251ED3F7FC68EB74080C5EC273DD